Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Make bundled Playwright discoverable by Dependabot via PackageDownload - #9449

Closed
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp
Closed

Make bundled Playwright discoverable by Dependabot via PackageDownload#9449
Amaury Levé (Evangelink) wants to merge 3 commits into
mainfrom
evangelink-supreme-lamp

Conversation

@Evangelink

Copy link
Copy Markdown
Member

Problem

Dependabot keeps Aspire.Hosting.Testing up to date but has never bumped Microsoft.Playwright.MSTest.v4 (still stuck at 1.60.0, while 1.61.0 has been available on the feeds since 2026-06-24). See #9362.

PR #9446 is the smoking gun: Aspire and Playwright sit in the identical orphan-CPM PackageVersion ItemGroup in Directory.Packages.props, yet that PR bumped only Aspire and left Playwright behind.

Root cause

The earlier "discoverability" workaround (#9365) assumed a literal PackageVersion in Directory.Packages.props was enough for Dependabot to track the package. It is not. Dependabot only proposes updates for packages that have a real consuming reference (PackageReference / PackageDownload). A lone orphan CPM PackageVersion with no consumer is invisible to it.

Aspire was only ever updated because it already had a PackageDownload in MSTest.Acceptance.IntegrationTests.csproj (used to stage the package for test assets). Playwright had no equivalent reference anywhere, so it was never discovered.

Fix

  • Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 next to the existing Aspire one in MSTest.Acceptance.IntegrationTests.csproj. This gives Dependabot a real reference to track; it will then bump both the MicrosoftPlaywrightVersion property and the literal PackageVersion, with the existing _ValidateBundledSdkFeatureVersions target keeping them in sync.
  • Correct the comments in Directory.Packages.props so they no longer credit the orphan PackageVersion alone, and document that any future bundled-but-unreferenced SDK feature package needs a matching PackageDownload.

Validation

MSTest.Acceptance.IntegrationTests restores and builds cleanly (0 warnings, 0 errors) with the new PackageDownload.

Closes#9362.

Co-authored-by: Copilot 223556219+Copilot@users.noreply.github.com

The orphan `PackageVersion` for `Microsoft.Playwright.MSTest.v4` in
Directory.Packages.props was never enough for Dependabot to discover and
bump it: Dependabot only proposes updates for packages that have a real
consuming reference (PackageReference / PackageDownload). Aspire.Hosting.Testing
sits in the same orphan-CPM ItemGroup but was kept up to date only because it
already had a PackageDownload in the acceptance-test project (see #9446, which
bumped Aspire but left Playwright stuck at 1.60.0).
Add a matching PackageDownload for Microsoft.Playwright.MSTest.v4 and update the
surrounding comments so future bundled SDK feature packages follow the same
pattern.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
CopilotAI review requested due to automatic review settings June 26, 2026 10:13

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses Dependabot “discoverability” for bundled MSTest SDK feature packages by adding a real consuming reference for Microsoft.Playwright.MSTest.v4 (via PackageDownload) and clarifying CPM/Dependabot guidance in comments.

Changes:

  • Add PackageDownload for Microsoft.Playwright.MSTest.v4 in MSTest.Acceptance.IntegrationTests.csproj to give Dependabot a concrete reference to track.
  • Update Directory.Packages.props comments to document that orphan CPM PackageVersion entries are not sufficient for Dependabot without a real reference.
Show a summary per file
FileDescription
test/IntegrationTests/MSTest.Acceptance.IntegrationTests/MSTest.Acceptance.IntegrationTests.csprojAdds a Playwright PackageDownload and expands comments explaining why it’s needed for Dependabot discoverability.
Directory.Packages.propsUpdates the “bundled but not directly referenced” section comments to document Dependabot behavior and the need for a matching consuming reference.

Review details

  • Files reviewed: 2/2 changed files
  • Comments generated: 3
  • Review effort level: Low

Comment on lines +46 to +48
These PackageDownload items also give Dependabot a real consuming reference for the
bundled MSTest.Sdk feature packages (Aspire/Playwright), which is what makes it discover
and bump them. A lone orphan PackageVersion in Directory.Packages.props is NOT enough:

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting this code. While this PR was open, main independently landed the same fix for #9362 using inert PackageReference ... ExcludeAssets="all" anchors for both Playwright and Aspire. After merging main, I reverted this branch's PackageDownload approach (and these comments) to match main exactly, so the wording flagged here no longer exists. This PR is now a no-op and will be closed as superseded.

<ItemGroup>
<PackageReference Include="Microsoft.Playwright.MSTest.v4" ExcludeAssets="all" />
<PackageReference Include="Aspire.Hosting.Testing" ExcludeAssets="all" />
<PackageDownload Include="Microsoft.Playwright.MSTest.v4" Version="[$(MicrosoftPlaywrightVersion)]" />

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, but moot now. main already fixed #9362 with an inert PackageReference ... ExcludeAssets="all" anchor for Playwright rather than a PackageDownload. That anchor is purely a Dependabot reference and excludes all assets, so there's no test-asset staging to keep consistent (the Playwright acceptance test restores Microsoft.Playwright.MSTest.v4 from the normal feeds, not from the local-tmp-packages feed). This branch has been reverted to match main, so the misplaced PackageDownload is gone.

Comment threadDirectory.Packages.props Outdated
Comment on lines +143 to +146
MSTest.Acceptance.IntegrationTests.csproj which is what actually triggers the update; Dependabot
then bumps both the *Version property and the literal PackageVersion below. If you add another
bundled-but-unreferenced SDK feature package here, add a matching PackageDownload too, otherwise
it will silently never be updated.

Copy link
Copy Markdown
MemberAuthor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Resolved by reverting to main's wording. main's comment already states the _ValidateBundledSdkFeatureVersions target enforces synchronization between the property and the literal PackageVersion, so the contradiction flagged here no longer exists on this branch.

CopilotAI review requested due to automatic review settings June 26, 2026 10:17
main independently fixed#9362 via inert PackageReference ExcludeAssets=\"all\"
anchors for both Playwright and Aspire. Revert this branch's PackageDownload-based
approach and the contradictory comments to match main exactly.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

CopilotAI review requested due to automatic review settings June 26, 2026 10:22

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@Evangelink

Copy link
Copy Markdown
MemberAuthor

🧪 Test quality grade — PR #9449

No new or modified test methods were identified in the changed regions
of this PR. Nothing to grade.

Re-run with /grade-tests.

🤖 Automated content by GitHub Copilot. Posted via a maintainer's GitHub token, so it appears under their account — the account owner did not write or approve this content personally. Generated by the Grade Tests on PR (on open / sync) workflow. · 194 AIC · ⌖ 12.8 AIC · ⊞ 43.7K · [◷]( · )

@Evangelink

Copy link
Copy Markdown
MemberAuthor

Closing as superseded. While this PR was open, main independently landed the same fix for #9362 — inert PackageReference ... ExcludeAssets="all" Dependabot anchors for both Microsoft.Playwright.MSTest.v4 and Aspire.Hosting.Testing (plus the _ValidateBundledSdkFeatureVersions drift guard). I merged main and reverted this branch's PackageDownload approach so its net diff against main is empty. The 1.61.0 bump will now flow through Dependabot via main's anchors. Review comments have been replied to as resolved.

auto-merge was automatically disabled June 26, 2026 10:47

Pull request was closed

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Update bundled Playwright for .NET version in MSTest SDK

2 participants

@Evangelink